Modify config in /etc/ssh or ssh_config to disable support for legacy protocols. Look for the 'Protocol 2,1' line and remove the ver 1 protocol.
Also set 'PermitRootLogin no' and 'MaxAuthTries 3'
After the changes have been made run:
service ssh restart
View attack activity by looking at /var/log/auth. If you see a particular IP that keeps attacking, put an entry in /etc/hosts.deny
You can automate this process by installing the DenyHosts package. Edit it's config in /etc/denyhosts.conf and change DENY_THRESHOLD_INVALID from 5 to 2
Search
Showing posts with label ssh. Show all posts
Showing posts with label ssh. Show all posts
Tuesday, 17 August 2010
Tuesday, 29 September 2009
Setup SSH without a password
Using the below steps, you can ssh to the server from client without the entering any password.
The machine which run the ssh command is the client
The machine that the client access using ssh is the server
- Run the following command on the client
- -> ssh-keygen -t dsa
- File id_dsa and id_dsa.pub will be created inside $HOME/.ssh
- Copy id_dsa.pub to the server’s .ssh directory
- -> scp $HOME/.ssh/id_dsa.pub user@server:/home/user/.ssh
- Change to /root/.ssh and create file authorized_keys containing id_dsa content
- -> cd /home/user/.ssh
- -> cat id_dsa >> authorized_keys
- You can try ssh to the server from the client and no password will be needed
- -> ssh user@server
- Run the following command on the client
- -> ssh-keygen -t dsa
- File id_dsa and id_dsa.pub will be created inside $HOME/.ssh
- Copy the id_dsa.pub to the server’s .ssh directory
- -> ssh-copy-id -i ~/.ssh/id_dsa.pub user@server
- You can try ssh to the server from the client and no password will be needed
- -> ssh user@server
Subscribe to:
Posts (Atom)